Last updated: 1 September 2026

Nexinity Sp. z o.o. (“Nexinity”, “we”, “us”) is a Polish factoring company: we purchase and collect outstanding invoices on behalf of our clients, which means we process personal data both about our clients (the businesses we work with) and about their debtors (the customers who owe and pay those invoices). Handling that data carefully and securely, in particular personal data, is a matter we take seriously.

This Privacy Policy explains, clearly and transparently, what personal data we collect as a website visitor, client or debtor of Nexinity, and what we do with it. Nexinity Sp. z o.o. is registered in Poland, with its registered office at Pl. Władysława Andersa 3, 11th floor, 61-894 Poznań, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0001260576, REGON: 545480044, NIP: 7831960893.

1. Personal data we process

Nexinity processes personal data from clients and their representatives, from debtors, and from visitors to our website. To keep this as clear as possible, we distinguish below between the website, our clients, and debtors.

Website visitors. When you visit our website, we process:

  • IP address;
  • Google Analytics data (anonymised);
  • Internet browser and device type;
  • Location data;
  • Use of our website.

Clients. When your business signs up to become a Nexinity client, we process:

  • The first and last name of your company’s representatives and beneficial owners;
  • Date of birth, place of birth, and nationality;
  • Address details;
  • Phone number;
  • Email address;
  • A copy of the document used to verify identity;
  • The number, date and place of issue of that identity document;
  • IP address, internet browser and device type;
  • Other personal data you actively provide, for example by creating a profile on our platform, in correspondence or by telephone.

Debtors. When a debtor pays an invoice that Nexinity has purchased from a client, or is contacted by us for collection purposes, we process:

  • Payment details (for example bank account number);
  • IP address, internet browser and device type (where payment is made online);
  • In some cases, first and last name;
  • In some cases, address details;
  • In some cases, information about the invoice, product or service underlying the debt;
  • Other personal data actively provided, for example in correspondence or by telephone.

2. Special or sensitive personal data

Nexinity does not seek to process special or sensitive categories of personal data about clients or debtors. As part of our fraud- and financial-crime prevention duties, we do check clients, their representatives and beneficial owners against sanctions, PEP and adverse-media screening lists, and we record the outcome of that screening. This does not involve processing criminal-conviction data.

We ask that clients and debtors do not otherwise share special categories of personal data with us. If you choose to share such data anyway, we will only process it where necessary for our services.

3. Why we process your personal data

We process personal data for the following purposes:

  • KYC and onboarding: Before we can purchase a client’s receivables, we need personal data from that client’s legal representatives, beneficial owners, and other relevant individuals, to assess whether they can become a Nexinity client. We may also use data obtained from third parties for this purpose. This has a legal basis under applicable anti-money-laundering and counter-terrorist-financing legislation.
  • Performance of the factoring agreement: Once a business becomes a client, we use personal data — including of the client’s debtors — to purchase, collect and reconcile receivables, and to communicate with debtors about outstanding invoices.
  • Legal obligations: We are subject to anti-money-laundering and counter-terrorist-financing obligations, under which we may be required to investigate unusual transactions or report information to competent authorities, such as Poland’s General Inspector of Financial Information (GIIF), the police, or the tax authorities.
  • Collections: Nexinity processes debtors’ personal data to collect payment on invoices purchased from our clients, and to manage reminders and dunning where an invoice is overdue.
  • Analysis: We process personal data for statistical analysis, including credit-risk scoring of debtors.
  • Training: We process personal data for the training and assessment of Nexinity staff.
  • Contact: We process personal data to respond when you contact us, for example through a website form, to request information or a proposal.

If Nexinity wishes to process your personal data for another purpose than described above, we will only do so after asking for and obtaining your explicit consent. You may withdraw that consent at any time, without giving a reason.

4. How long we keep your personal data

We keep personal data only for as long as reasonably necessary for the purposes listed above.

If your business becomes a Nexinity client, we keep data relating to that business relationship for 7 years after the end of the Factoring Agreement. Data collected to satisfy our KYC and anti-money-laundering obligations is kept for as long as we are legally required to, generally at least 7 years after the relationship ends.

Data relating to debtors is kept for as long as needed to collect the relevant receivable and to satisfy our record-keeping obligations, generally in line with the same 7-year period.

Data about questions, comments or support requests from people who are not clients or debtors is kept for 2 years.

These retention periods may be longer where applicable law requires it, or where we need to keep information to protect our legal rights until a relevant claim has been settled.

5. Do we share your personal data with third parties?

Nexinity shares personal data with third parties where necessary to perform the Factoring Agreement or to comply with a legal obligation — for example with credit insurers, credit bureaus, or payment and banking infrastructure providers. Where a third party processes personal data on our behalf, we enter into a data processing agreement with that party, and we require your personal data to be protected to at least the same standard we apply ourselves. Nexinity remains fully responsible for these processing activities and takes reasonable administrative, technical and physical measures to protect your personal data against unauthorised access, loss or alteration.

Where we wish to share your personal data with a third party outside the scope described above, we will only do so after asking for and obtaining your explicit consent.

6. Cookies

Our website uses cookies and similar technologies to understand how visitors use the site and to improve it. Functional cookies ensure the website works properly; with your consent, we also use analytics cookies (with IP addresses anonymised) to understand website usage. We do not use cookies for third-party advertising purposes.

For full details of the individual cookies we use, their purpose and duration, and to manage your preferences, see our Cookie Policy.

7. Your rights

You have the right to access, correct, restrict or request deletion of the personal data Nexinity processes about you, unless we are unable to grant this on the basis of a legal obligation. You can send such a request to compliance@nexinity.eu or by post to our registered office (Pl. Władysława Andersa 3, 11th floor, 61-894 Poznań, Poland). To confirm your identity, we may ask you to include a copy of an identity document with sensitive fields (photo, machine-readable zone, document number, national ID number) blacked out. We will respond to your request as soon as possible, and in any case within one month.

You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), or with the supervisory authority in your own EU member state.

8. Security of your personal data

Nexinity is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and has taken steps accordingly. We maintain technical and organisational measures designed to prevent unauthorised access to, and to safeguard the confidentiality, integrity and availability of, the personal data we process.

9. Nexinity’s role under the GDPR

Nexinity acts as controller for the personal data of its clients and their representatives, since we determine what data we need to assess and onboard a client and to satisfy our own legal obligations.

In relation to debtors, Nexinity is also controller: collecting payment on receivables we have purchased from our clients is a core Nexinity activity, and we determine what personal data is needed to do so. Where a client provides us with debtor data (such as name, address and invoice details) so that we can pursue collection on their behalf, we process that data as necessary to deliver the factoring service. For the processing we carry out on behalf of a client in this way, we enter into a data processing agreement with that client.

10. Data protection contact

Nexinity has designated a data protection contact responsible for overseeing our processing of personal data and for advising on data protection matters, reachable at compliance@nexinity.eu.

11. Contact

Questions, comments, requests or complaints about this Privacy Policy, or about how we process your personal data, are welcome and can be addressed to compliance@nexinity.eu or to Pl. Władysława Andersa 3, 11th floor, 61-894 Poznań, Poland.